Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot process.
| Software | From | Fixed in |
|---|---|---|
| kapsch / ris-9160_firmware | 3.2.0.829.23 | 3.2.0.829.23.x |
| kapsch / ris-9160_firmware | 3.8.0.1119.42 | 3.8.0.1119.42.x |
| kapsch / ris-9160_firmware | 4.6.0.1211.28 | 4.6.0.1211.28.x |
| kapsch / ris-9260_firmware | 3.2.0.829.23 | 3.2.0.829.23.x |
| kapsch / ris-9260_firmware | 3.8.0.1119.42 | 3.8.0.1119.42.x |
| kapsch / ris-9260_firmware | 4.6.0.1211.28 | 4.6.0.1211.28.x |